PDF-Derived Verification Requirements
The PDF requires that: the Board approves the RMF, risk appetite, and material risk policies and receives regular reporting on Bitkaya’s overall risk profile, material incidents, control weaknesses, and remediation status; the Risk & Compliance Committee reviews the risk profile, limit breaches, incident trends, remediation status, new product risks, and material control issues and challenges management; Executive Management owns execution and ensures appropriate staffing, tools, systems, reporting, and governance; first line functions own risks and operate controls; second line (Risk and Compliance) establishes policy standards, advises, monitors adherence, performs challenge, reviews escalations, and supports reporting; third line provides independent review. The full risk taxonomy includes: financial crime risks (ML, TF, PF, sanctions, bribery, corruption, fraud, market abuse); market and liquidity; operational; technology and cybersecurity; safeguarding and custody; legal and regulatory compliance; counterparty, third-party, and outsourcing; strategic and business model; reputational; business continuity and resilience. Risk appetite is low or very low for regulatory breaches, client harm, misuse of client assets, sanctions violations, bribery/corruption, cybersecurity compromise, and AML/CTF/CPF failures. Appetite is expressed through qualitative statements and quantitative indicators with escalation thresholds and management information. Where thresholds are breached or control effectiveness deteriorates, management must assess whether additional controls, temporary restrictions, enhanced monitoring, or remediation actions are required.
Objective
Ensure risk responsibilities, taxonomy, appetite, thresholds and authorities remain complete, approved and current per the RMF governance framework, three lines model, risk taxonomy, and risk appetite statement.
Control Activity
Compliance coordinates annual and event-driven review of the governance matrix, risk taxonomy, appetite, limits and escalation authorities and obtains Board approval. The review verifies that: the Board’s role in approving the RMF and receiving risk-profile reporting is documented; the Risk & Compliance Committee’s challenge and review responsibilities are defined; Executive Management’s ownership of execution is clear; first/second/third line responsibilities are separated; the taxonomy covers all required categories; appetite statements are low or very low for the specified risk types; and quantitative indicators, tolerances, and escalation thresholds are defined with management information support.
Evidence
- Expected evidence: Governance and responsibility matrix covering Board, Risk & Compliance Committee, Executive Management, first line, second line, and third line responsibilities
- Expected evidence: Risk taxonomy covering all required categories (financial crime including ML/TF/PF/sanctions/bribery/corruption/fraud/market abuse; market and liquidity; operational; technology and cybersecurity; safeguarding and custody; legal and regulatory compliance; counterparty/third-party/outsourcing; strategic and business model; reputational; business continuity and resilience)
- Expected evidence: Risk appetite statement with low/very low appetite for regulatory breaches, client harm, misuse of client assets, sanctions violations, bribery/corruption, cybersecurity compromise, and AML/CTF/CPF failures, expressed through qualitative statements and quantitative indicators with escalation thresholds
- Expected evidence: Breach and escalation records documenting where thresholds were breached or control effectiveness deteriorated, with management assessment of additional controls, temporary restrictions, enhanced monitoring, or remediation
- Expected evidence: Management and Board review and approval
- Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: inspect annual approval and sample material risks and breaches for assigned ownership, threshold application, authorized decision, and documented management response to threshold breaches or control deterioration
- Testing frequency: annual and after material change
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Procedure: PROC-RMF-001 Govern Risk Appetite Taxonomy and Accountability
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved RMF version 1.1.